Felter må ikke være obligatoriske
HiJeg har denne fil:
===========================
<?php
include_once'logincheck.php';
include_once("myconnect.php");
include_once("check_msg_function.php");
function RTESafe($strText) {
//returns safe code for preloading in the RTE
$tmpString = trim($strText);
//convert all types of single quotes
$tmpString = str_replace(chr(145), chr(39), $tmpString);
$tmpString = str_replace(chr(146), chr(39), $tmpString);
$tmpString = str_replace("'", "'", $tmpString);
//convert all types of double quotes
$tmpString = str_replace(chr(147), chr(34), $tmpString);
$tmpString = str_replace(chr(148), chr(34), $tmpString);
// $tmpString = str_replace("\"", "\"", $tmpString);
//replace carriage returns & line feeds
$tmpString = str_replace(chr(10), " ", $tmpString);
$tmpString = str_replace(chr(13), " ", $tmpString);
return $tmpString;
}
$errcnt=0;
if(count($_POST)<>0) //IF SOME FORM WAS POSTED DO VALIDATION
{
/////////---getting config---------
$sbq_con='select * from sbbleads_config where sb_id=1';
$sbrow_con=mysql_fetch_array(mysql_query($sbq_con));
$sbq_gro='select * from sbbleads_groups where sb_memtype='.$_SESSION["sbbleads_memtype"];
$sbrow_gro=mysql_fetch_array(mysql_query($sbq_gro));
/////////--------------getting information bout user's privious postings
$sbq_off="select * from sbbleads_offers where sb_uid=".$_SESSION["sbbleads_userid"];
$sbsell_count=mysql_num_rows(mysql_query($sbq_off));
//////////////////////////////////---------------------------
if( $sbsell_count >= $sbrow_gro["sb_sell_cnt"] )
{
header("Location: gen_confirm_mem.php?err=post_offer&errmsg=".urlencode("Sorry, some error occurred and unable to post sell offer."));
die();
}
////////////////////--------------------
$sb_cat_list=str_replace(";",",",$_REQUEST["category"]);
$cid_list=str_replace(";",",",$_REQUEST["cid"]);
$cat=explode(",",$cid_list);
// $cat_name=explode(",",$_REQUEST["category"]);
$sb_title=$_REQUEST["sb_title"];
$sb_description=$_REQUEST["sb_description"];
$sb_quantity=$_REQUEST["sb_quantity"];
$sb_keywords=$_REQUEST["sb_keywords"];
$key=explode(",",$sb_keywords);
$sb_location=$_REQUEST["sb_location"];
$sb_min_order=$_REQUEST["sb_min_order"];
$sb_price_cur_id=$_REQUEST["sb_price_cur_id"];
$sb_price=$_REQUEST["sb_price"];
$sb_samples_available=$_REQUEST["sb_samples_available"];
$sb_product_status=$_REQUEST["sb_product_status"];
$sb_delivery_time=$_REQUEST["sb_delivery_time"];
$sb_payment_mode='-1';
if(isset($_REQUEST["sb_cash"]) && ($_REQUEST["sb_cash"]=='yes') )
$sb_payment_mode.=',cash';
if(isset($_REQUEST["sb_cheque"]) && ($_REQUEST["sb_cheque"]=='yes') )
$sb_payment_mode.=',cheque';
if(isset($_REQUEST["sb_credit"]) && ($_REQUEST["sb_credit"]=='yes') )
$sb_payment_mode.=',credit';
if(isset($_REQUEST["sb_bank"]) && ($_REQUEST["sb_bank"]=='yes') )
$sb_payment_mode.=',bank';
if(isset($_REQUEST["sb_loc"]) && ($_REQUEST["sb_loc"]=='yes') )
$sb_payment_mode.=',loc';
if(isset($_REQUEST["sb_escrow"]) && ($_REQUEST["sb_escrow"]=='yes') )
$sb_payment_mode.=',escrow';
//echo $sb_payment_mode;
$sb_other_mode=$_REQUEST["sb_other_mode"];
$sb_shipping_cost=$_REQUEST["sb_shipping_cost"];
// echo $cid_list."---hello";
if( $cid_list == '' )
{
$errs[$errcnt]="Atleast one Category must be provided";
$errcnt++;
}
elseif(count($cat) > $sbrow_gro["sb_cat_cnt"])
{
$errs[$errcnt]="Too many Categories provided";
$errcnt++;
}
if ( strlen(trim($sb_title)) == 0 )
{
$errs[$errcnt]="Title must be provided";
$errcnt++;
}
elseif(preg_match ("/[<>&]/", $sb_title))
{
$errs[$errcnt]="Title can not have any special character i.e. & < >";
$errcnt++;
}
if ( strlen(trim($sb_description)) == 0 )
{
$errs[$errcnt]="Description must be provided";
$errcnt++;
}
elseif ( strlen(strip_tags($sb_description)) > $sbrow_con['sb_description_length'] )
{
$errs[$errcnt]="Description length must not exceed ".$sbrow_con['sb_description_length']." characters";
$errcnt++;
}
elseif( $sbrow_con["sb_approval_type_offer"] == 'auto')
{
if ( check_msg($sb_description,0) == 'yes' )
{
$errs[$errcnt]="Description must not contain bad words";
$errcnt++;
}
}
if ( !is_numeric($sb_quantity) || ($sb_quantity <= 0) )
{
$errs[$errcnt]="Quantity must be non-zero positive integer";
$errcnt++;
}
if ( strlen(trim($sb_keywords)) == 0 )
{
$errs[$errcnt]="Keywords must be provided";
$errcnt++;
}
elseif(preg_match ("/[<>&]/", $sb_keywords))
{
$errs[$errcnt]="Keywords can not have any special character i.e. & < >";
$errcnt++;
}
elseif(count($key) > $sbrow_gro["sb_keyword_cnt"])
{
$errs[$errcnt]="Too many keywords provided";
$errcnt++;
}
if ( strlen(trim($sb_location)) == 0 )
{
$errs[$errcnt]="Location must be provided";
$errcnt++;
}
elseif(preg_match ("/[<>&]/", $sb_location))
{
$errs[$errcnt]="Location can not have any special character i.e. & < >";
$errcnt++;
}
if ( !is_numeric($sb_min_order) || ($sb_min_order <= 0) )
{
$errs[$errcnt]="Minimum Order must be non-zero positive integer";
$errcnt++;
}
if ( !is_numeric($sb_price_cur_id) || ($sb_price_cur_id == 0) )
{
$errs[$errcnt]="Price currency must be selected";
$errcnt++;
}
if ( !is_numeric($sb_price) || ($sb_price <= 0) )
{
$errs[$errcnt]="Price must be non-zero positive number";
$errcnt++;
}
if ( !is_numeric($sb_delivery_time) || ($sb_delivery_time < 0) )
{
$errs[$errcnt]="Delivery Time must be positive integer";
$errcnt++;
}
if ( !isset($_REQUEST["sb_cash"]) && !isset($_REQUEST["sb_cheque"]) && !isset($_REQUEST["sb_credit"]) && !isset($_REQUEST["sb_bank"]) && !isset($_REQUEST["sb_loc"]) && !isset($_REQUEST["sb_escrow"]) && (strlen(trim($sb_other_mode))==0) )
{
$errs[$errcnt]="Atleast one Payment Mode must be provided";
$errcnt++;
}
//if ( !is_numeric($sb_shipping_cost) || ($sb_shipping_cost < 0) )
//{
//$errs[$errcnt]="Shipping Cost must be positive number";
//$errcnt++;
//}
if($errcnt==0)
{
if(!get_magic_quotes_gpc())
{
$sb_title=str_replace("$","\$",addslashes($sb_title));
$sb_description=str_replace("$","\$",addslashes($sb_description));
$sb_quantity=str_replace("$","\$",addslashes($sb_quantity));
$sb_keywords=str_replace("$","\$",addslashes($sb_keywords));
$sb_location=str_replace("$","\$",addslashes($sb_location));
$sb_samples_available=str_replace("$","\$",addslashes($sb_samples_available));
$sb_product_status=str_replace("$","\$",addslashes($sb_product_status));
$sb_other_mode=str_replace("$","\$",addslashes($sb_other_mode));
}
else
{
$sb_title=str_replace("$","\$",$sb_title);
$sb_description=str_replace("$","\$",$sb_description);
$sb_quantity=str_replace("$","\$",$sb_quantity);
$sb_keywords=str_replace("$","\$",$sb_keywords);
$sb_location=str_replace("$","\$",$sb_location);
$sb_samples_available=str_replace("$","\$",$sb_samples_available);
$sb_product_status=str_replace("$","\$",$sb_product_status);
$sb_other_mode=str_replace("$","\$",$sb_other_mode);
}
$sb_min_order=(int)$sb_min_order;
$sb_price_cur_id=(int)$sb_price_cur_id;
$sb_price=$sb_price;
$sb_delivery_time=(int)$sb_delivery_time;
$sb_shipping_cost=$sb_shipping_cost;
$sb_postedon=date("YmdHis",time());
$sb_approved='yes';
$sb_uid=$_SESSION["sbbleads_userid"];
// $sb_expireson=;
$sbq_con='select * from sbbleads_config where sb_id=1';
$sbrow_con=mysql_fetch_array(mysql_query($sbq_con));
if($sbrow_con['sb_approval_type_offer']=='auto')
{
$sb_new='no';
$sb_approved='yes';
$sb_msg='Your sell offer has been posted successfully.';
}
else
{
$sb_new='yes';
$sb_approved='no';
$sb_msg='Your sell offer has been sent for admin approval.';
}
$sbqi_off="Insert into `sbbleads_offers` (sb_uid, sb_title, sb_description, sb_quantity, sb_postedon, sb_keywords, sb_location, sb_min_order, sb_price_cur_id, sb_price, sb_samples_available, sb_product_status, sb_delivery_time, sb_payment_mode, sb_other_mode, sb_shipping_cost, sb_approved, sb_new) values ($sb_uid, '$sb_title', '$sb_description', $sb_quantity, $sb_postedon, '$sb_keywords', '$sb_location', $sb_min_order, $sb_price_cur_id, $sb_price, '$sb_samples_available', '$sb_product_status', $sb_delivery_time, '$sb_payment_mode', '$sb_other_mode', $sb_shipping_cost, '$sb_approved', '$sb_new')";
// die($sbqi_off);
mysql_query($sbqi_off);
if(mysql_affected_rows()>0)
{
///-adding to categories
$sbq_off="select max(sb_id) as max_id from sbbleads_offers where 1";
$sbrow_off=mysql_fetch_array(mysql_query($sbq_off));
$sb_offer_id=$sbrow_off["max_id"];
foreach($cat as $sb_value)
{
$sbq_off_cat="select * from sbbleads_offer_cats where sb_offer_id=$sb_offer_id and sb_cid=$sb_value";
//echo $sbq_off_cat;
// $sbrs_off_cat=
if( mysql_num_rows(mysql_query($sbq_off_cat)) > 0 )
continue; //skips if record already exists
$sbqi_off_cat="insert into sbbleads_offer_cats (sb_offer_id, sb_cid) values ($sb_offer_id, $sb_value)";
mysql_query($sbqi_off_cat);
}
////--------mail to member/admin if approval is not auto
if($sbrow_con['sb_approval_type_offer']<>'auto')
{
//SENDING MAIL TO MEMBER////////////////////////
// $sbq_res="select * from sbrrs_resources where sbres_id=$sbres_id";
// $sbrow_res=mysql_fetch_array(mysql_query($sbq_res));
$sbq_mem="select * from sbbleads_members where sb_id=".$_SESSION["sbbleads_userid"];
$sbrow_mem=mysql_fetch_array(mysql_query($sbq_mem));
$rs_con=mysql_fetch_array(mysql_query("select * from sbbleads_config where sb_id=1"));
$sb_null_char=$rs_con["sb_null_char"];
$login_url=$rs_con["sb_site_root"]."/signin.php";
// $sbresource_url=$rs_con["sbsite_addr"]."/details_res.php?sbres_id=$sbres_id";
//Reads email to be sebt
$sbq_mail="SELECT * FROM sbbleads_mails where sb_mailid=6";
$sbrs_mail=mysql_query($sbq_mail);
if ( $sbrow_mail=mysql_fetch_array($sbrs_mail) )
{
$from =$sbrow_mail["sb_fromid"];
$to = $sbrow_mem["sb_email"];
$subject =$sbrow_mail["sb_subject"];
$header="From:" . $from . "\r\n" ."Reply-To:". $from ;
$body=str_replace("%email%", $sbrow_mem["sb_email"],str_replace("%password%",$sbrow_mem["sb_password"],str_replace("%lname%", $sbrow_mem["sb_lastname"],str_replace("%fname%",$sbrow_mem["sb_firstname"],str_replace("%username%",$sbrow_mem["sb_username"], $sbrow_mail["sb_mail"]) ))));
$body=str_replace("%signup_url%",$sb_null_char,str_replace("%login_url%",$login_url,$body));
$body=str_replace("%message_text%",$sb_null_char,str_replace("%message_title%",$sb_null_char,str_replace("%sender_username%",$sb_null_char,str_replace("%message_date%",$sb_null_char,$body))));
$body=str_replace("%visitor_name%",$sb_null_char,$body);
$body=str_replace("%offer_title%",$sb_title,str_replace("%offer_url%",$sb_null_char,str_replace("%offer_id%",$sb_null_char,$body)));
if(isset($sbrow_mail["sb_html_format"])&&($sbrow_mail["sb_html_format"]=="yes"))
{
$header .= "MIME-Version: 1.0\r\n";
$header .= "Content-type: text/html; charset=iso-8859-1\r\n";
// $body=str_replace("\n","<br>",$body);
}
// echo "--from:-$from----to:-$to---sub:-$subject----head:-$header----";
// echo "<pre>$body</pre>";
// die();
if( $sbrow_mail["sb_status"]=='yes')
mail($to,$subject,$body,$header);
}
//////////////////////////////////////////////////////////
///// Sending mail to admin
$rs0=mysql_fetch_array(mysql_query("select * from sbbleads_config where sb_id=1"));
//$login_url=$site_root[0]."/signinform.php";
//Reads email to be sebt
$sbq_mail="SELECT * FROM sbbleads_mails where sb_mailid=7";
$sbrs_mail=mysql_query($sbq_mail);
if ( $sbrow_mail=mysql_fetch_array($sbrs_mail) )
{
$from =$sbrow_mail["sb_fromid"];
$to = $rs0["sb_admin_email"];
$subject =$sbrow_mail["sb_subject"];
$header="From:" . $from . "\r\n" ."Reply-To:". $from ;
// $body=$rs["mail"];
$body=str_replace("%email%", $sbrow_mem["sb_email"],str_replace("%password%",$sb_null_char,str_replace("%lname%", $sbrow_mem["sb_lastname"],str_replace("%fname%",$sbrow_mem["sb_firstname"],str_replace("%username%",$sbrow_mem["sb_username"], $sbrow_mail["sb_mail"]) ))));
$body=str_replace("%signup_url%",$sb_null_char,str_replace("%login_url%",$login_url,$body));
$body=str_replace("%message_text%",$sb_null_char,str_replace("%message_title%",$sb_null_char,str_replace("%sender_username%",$sb_null_char,str_replace("%message_date%",$sb_null_char,$body))));
$body=str_replace("%visitor_name%",$sb_null_char,$body);
$body=str_replace("%offer_title%",$sb_title,str_replace("%offer_url%",$sb_null_char,str_replace("%offer_id%",$sb_null_char,$body)));
if(isset($sbrow_mail["sb_html_format"])&&($sbrow_mail["sb_html_format"]=="yes"))
{
$header .= "MIME-Version: 1.0\r\n";
$header .= "Content-type: text/html; charset=iso-8859-1\r\n";
// $body=str_replace("\n","<br>",$body);
}
// echo "--from:-$from----to:-$to---sub:-$subject----head:-$header----";
// echo "<pre>$body</pre>";
// die();
if( $sbrow_mail["sb_status"]=='yes')
mail($to,$subject,$body,$header);
}
} //end if approval <> 'auto'
elseif($sbrow_con['sb_approval_type_offer']=='auto')
{
/*/////-------mail to fav cats but if approval is auto 'coz otherwise it would be unapproved
$sbq_mail="SELECT * FROM sbbleads_mails where sb_mailid=24";
$sbrs_mail=mysql_query($sbq_mail);
if ( ($sbrow_mail=mysql_fetch_array($sbrs_mail)) && ($sbrow_mail['sb_status']=='yes'))
{
////////----------getting full path ids
/////////////////////////////////////////////////////
$cat_query=mysql_query("Select * from sbbleads_categories where sb_id in ($cid_list)");
$temp_cid_list=-1;
while ($rs=mysql_fetch_array($cat_query))
{
$temp_cid_list .=",".$rs["sb_id"];
$cid=$rs["sb_id"];
$cat_query1=mysql_query("Select * from sbbleads_categories where sb_id=" . $cid );
while ($rs1=mysql_fetch_array($cat_query1))
{
$temp_cid_list.="," .$rs1["sb_id"];
$cat_query1=mysql_query("Select * from sbbleads_categories where sb_id=" . $rs1["sb_pid"] );
}
}
$cid_list=$temp_cid_list;
//echo "<br>cats----".$temp_cid_list."----<br>";
//die();
//////-----------------------------------------
$rs_con=mysql_fetch_array(mysql_query("select * from sbbleads_config where sb_id=1"));
$sb_null_char=$rs_con["sb_null_char"];
$login_url=$rs_con["sb_site_root"]."/signin.php";
$sb_offer_url=$rs_con["sb_site_root"]."/view_offer?id=$sb_offer_id";
$sbuser_id_list="-1";
$sbq_fav_cat="select * from sbbleads_fav_cats where sb_type='sell' and cid in ($cid_list)";
// echo $sbq_fav_cat;
$sbrs_fav_cat=mysql_query($sbq_fav_cat);
while($sbrow_fav_cat=mysql_fetch_array($sbrs_fav_cat))
{
$sbuser_id_list.=",".$sbrow_fav_cat["mid"];
}
// echo "<br>user list".$sbuser_id_list."<br>";
$sbq3_mem="select * from sbbleads_members where sb_id in ($sbuser_id_list)";
// echo $sbq3_mem;
$sbrs3_mem=mysql_query($sbq3_mem);
while($sbrow3_mem=mysql_fetch_array($sbrs3_mem))
{ //send mail
//////---getting category name only first matching cat for a user
$sbq1_fav_cat="select * from sbbleads_fav_cats where cid in ($cid_list) and mid=".$sbrow3_mem["sb_id"];
//echo $sbq_off_cat;
$sbrs1_fav_cat=mysql_query($sbq1_fav_cat);
$sbrow_fav_cat=mysql_fetch_array($sbrs1_fav_cat);
$sbq4_cat="select * from sbbleads_categories where sb_id=".$sbrow_fav_cat["cid"];
//echo $sbq_off_cat;
$sbrow4_cat=mysql_fetch_array(mysql_query($sbq4_cat));
$sb_cat_name=$sbrow4_cat["sb_cat_name"];
///////----------------------
$from =$sbrow_mail["sb_fromid"];
$to = $sbrow3_mem["sb_email"];
$subject =$sbrow_mail["sb_subject"];
$header="From:" . $from . "\r\n" ."Reply-To:". $from ;
$body=str_replace("%email%", $sb_null_char,str_replace("%password%",$sb_null_char,str_replace("%lname%", $sbrow3_mem["sb_lastname"],str_replace("%fname%",$sbrow3_mem["sb_firstname"],str_replace("%username%",$sbrow3_mem["sb_username"], $sbrow_mail["sb_mail"]) ))));
$body=str_replace("%signup_url%",$sb_null_char,str_replace("%login_url%",$login_url,$body));
$body=str_replace("%message_text%",$sb_null_char,str_replace("%message_title%",$sb_null_char,str_replace("%sender_username%",$sb_null_char,str_replace("%message_date%",$sb_null_char,$body))));
$body=str_replace("%visitor_name%",$sb_null_char,$body);
$body=str_replace("%offer_title%",$sb_title,str_replace("%offer_url%",$sb_offer_url,str_replace("%offer_id%",$sb_offer_id,$body)));
$body=str_replace("%category%",$sb_cat_name,$body);
if(isset($sbrow_mail["sb_html_format"])&&($sbrow_mail["sb_html_format"]=="yes"))
{
$header .= "MIME-Version: 1.0\r\n";
$header .= "Content-type: text/html; charset=iso-8859-1\r\n";
// $body=str_replace("\n","%br>",$body);
}
// echo "--from:-$from----to:-$to---sub:-$subject----head:-$header----";
// echo "<pre>$body</pre>";
// die();
if( $sbrow_mail["sb_status"]=='yes')
mail($to,$subject,$body,$header);
} //end while sbrow3_mem
//////////////////////////////////////////////////////////
} // end if
//die();*/
} //end if approval == auto
///////////-----------------
if($sb_approved=="yes")
{
header ("Location: gen_confirm_mem.php?sb_type=1&id=$sb_offer_id&errmsg=".urlencode($sb_msg));
}
else
{
header ("Location: gen_confirm_mem.php?errmsg=".urlencode($sb_msg));
}
die();
}// if inserted
else
{
header("Location: gen_confirm_mem.php?err=post_offer&errmsg=".urlencode("Sorry, some error occurred and unable to post sell offer."));
die();
}
}// if no errors
}// if form posted
else
{
/////////---getting config---------
$sbq_con='select * from sbbleads_config where sb_id=1';
$sbrow_con=mysql_fetch_array(mysql_query($sbq_con));
$sbq_gro='select * from sbbleads_groups where sb_memtype='.$_SESSION["sbbleads_memtype"];
$sbrow_gro=mysql_fetch_array(mysql_query($sbq_gro));
/////////--------------getting information bout user's privious postings
$sbq_off="select * from sbbleads_offers where sb_uid=".$_SESSION["sbbleads_userid"];
$sbsell_count=mysql_num_rows(mysql_query($sbq_off));
//////////////////////////////////---------------------------
if( $sbsell_count >= $sbrow_gro["sb_sell_cnt"] )
{
header("Location: gen_confirm_mem.php?errmsg=".urlencode("You have already posted maximum allowed sell offers."));
die();
}
$cid_list='';
$sb_cat_list='';
$sb_title='';
$sb_description='';
$sb_quantity='';
$sb_keywords='';
$sb_location='';
$sb_min_order='';
$sb_price_cur_id='';
$sb_price='';
$sb_samples_available='no';
$sb_product_status='New';
$sb_delivery_time='';
$sb_payment_mode='';
$sb_other_mode='';
$sb_shipping_cost='';
}
function main ()
{
global $sbsell_count, $sbrow_con, $sbrow_gro, $errs, $errcnt, $cid_list, $sb_cat_list, $sb_title, $sb_description, $sb_quantity, $sb_keywords, $sb_location, $sb_min_order, $sb_price_cur_id, $sb_price, $sb_samples_available, $sb_product_status, $sb_delivery_time, $sb_payment_mode, $sb_other_mode, $sb_shipping_cost;
$showform="";
if (count($_POST)>0)
{
$cid_list=$_POST["cid"];
$sb_cat_list=$_POST["category"];
if ( $errcnt <> 0 )
{
?>
<table width="90%" border="0" align="center" cellpadding="2" cellspacing="0" class="errorstyle">
<tr>
<td colspan="2"><strong> Your request cannot be processed due to following
reasons</strong></td>
</tr>
<tr height="10">
<td colspan="2"></td>
</tr>
<?
for ($i=0;$i<$errcnt;$i++)
{
?>
<tr valign="top">
<td width="6%"> <?php echo $i+1;?></td>
<td width="94%"><?php echo $errs[$i]; ?></td>
</tr>
<?
}
?>
</table>
<?
}
}
if ($showform<>"No")
{
?>
<script language="JavaScript" type="text/javascript" src="richtext.js"></script>
<script language="JavaScript">
function add_category()
{
if(document.form123.cats.value!=0)
{
var id=document.form123.cats.selectedIndex;
//////-------checking duplicate category
var cid_list=form123.cid.value.split(";");
var cnt=0;
var posted="no";
while(cnt<cid_list.length)
{
if(cid_list[cnt]==document.form123.cats.value)
{ posted="yes";}
cnt++;
}
if(posted=="yes")
{
alert('This category is already in the list');
return false;
}
//////-------end checking duplicate category
//////-------checking max no. of categories
var sblength;
if(document.form123.category.value == "")
sblength=0;
else
sblength=cid_list.length
if( sblength >= <?php echo $sbrow_gro["sb_cat_cnt"]; ?> )
{
alert("You can't choose more than <?php echo ($sbrow_gro["sb_cat_cnt"]==1)?$sbrow_gro["sb_cat_cnt"].' category':$sbrow_gro["sb_cat_cnt"].' categories'; ?>");
return false;
}
//////-------checking max no. of categories
if(document.form123.category.value=="")
{
document.form123.cid.value=document.form123.cats.value;
document.form123.category.value=document.form123.cats.options[id].text;
document.form123.category.focus();
document.form123.cats.selectedIndex=0;
}
else
{
document.form123.cid.value=document.form123.cid.value+";"+document.form123.cats.value;
document.form123.category.value=document.form123.category.value+";"+document.form123.cats.options[id].text;
document.form123.category.focus();
document.form123.cats.selectedIndex=0;
}
}
else
{
alert('Choose a Category to add');
}
}
function remove_category()
{
var s1=window.document.form123.category.value;
var s2=s1.split(";");
var i=0;
var id=document.form123.cats.selectedIndex;
var s3=document.form123.cats.options[id].text;
var id_list=document.form123.cid.value;
var id_split=id_list.split(";");
var rem_id=document.form123.cats.value;
window.document.form123.category.value="";
window.document.form123.cid.value="";
while(i<s2.length)
{
//alert('Checking '+s2[i]+' nnn with'+s3+' mm');
if(s3==s2[i])
{
//continue;
// alert('Removing'+s3);
}
else
{
if(document.form123.category.value=="")
{
document.form123.category.value=s2[i];
}
else
{
document.form123.category.value=document.form123.category.value+";"+s2[i];
}
}
if(rem_id==id_split[i])
{
//continue;
// alert('Removing'+s3);
}
else
{
if(document.form123.cid.value=="")
{
document.form123.cid.value=id_split[i];
}
else
{
document.form123.cid.value=document.form123.cid.value+";"+id_split[i];
}
}
i++;
}
//window.document.form123.related.value="";
//window.document.form123.rel_id.value="";
}
<?php
?>
function validate_form(frm)
{
updateRTEs();
if(frm.cid.value=='')
{
alert('Please choose atleast one category');
frm.cats.focus();
return(false);
}
if(frm.sb_title.value=='')
{
alert('Please specify Title');
frm.sb_title.focus();
return(false);
}
else if(frm.sb_title.value.match(/[&<>]+/))
{
alert("Please remove special characters from Title i.e. & < >");
frm.sb_title.focus();
frm.sb_title.select();
return(false);
}
if(frm.sb_description.value=='')
{
alert('Please specify Description');
return(false);
}
if( isNaN(frm.sb_quantity.value) || frm.sb_quantity.value<=0)
{
alert('Please specify Quantity as a non-zero positive integer');
frm.sb_quantity.focus();
frm.sb_quantity.select();
return(false);
}
if(frm.sb_keywords.value=='')
{
alert('Please specify Keywords');
frm.sb_keywords.focus();
return(false);
}
else if(frm.sb_keywords.value.match(/[&<>]+/))
{
alert("Please remove special characters from Keywords i.e. & < >");
frm.sb_keywords.focus();
frm.sb_keywords.select();
return(false);
}
else
{
var list=frm.sb_keywords.value.split(",");
if( list.length > <?php echo $sbrow_gro["sb_keyword_cnt"]; ?> )
{
alert("You can't specify more than <?php echo ($sbrow_gro["sb_keyword_cnt"]==1)?$sbrow_gro["sb_keyword_cnt"].' keyword':$sbrow_gro["sb_keyword_cnt"].' keywords'; ?>");
frm.sb_keywords.focus();
frm.sb_keywords.select();
return(false);
}
}
if(frm.sb_location.value=='')
{
alert('Please specify Location');
frm.sb_location.focus();
return(false);
}
else if(frm.sb_location.value.match(/[&<>]+/))
{
alert("Please remove special characters from Location i.e. & < >");
frm.sb_location.focus();
frm.sb_location.select();
return(false);
}
if( isNaN(frm.sb_min_order.value) || frm.sb_min_order.value<=0)
{
alert('Please specify Minimum Order as a non-zero positive integer');
frm.sb_min_order.focus();
frm.sb_min_order.select();
return(false);
}
else if( parseInt(frm.sb_min_order.value) > parseInt(frm.sb_quantity.value) )
{
alert("Minimum Order can't be more than Quantity");
frm.sb_min_order.focus();
frm.sb_min_order.select();
return(false);
}
if( frm.sb_price_cur_id.value == 0)
{
alert('Please choose currency for Price');
frm.sb_price_cur_id.focus();
return(false);
}
if( isNaN(frm.sb_price.value) || frm.sb_price.value<=0)
{
alert('Please specify Price as a non-zero positive number');
frm.sb_price.focus();
frm.sb_price.select();
return(false);
}
if( isNaN(frm.sb_delivery_time.value) || frm.sb_delivery_time.value < 0 || frm.sb_delivery_time.value=='')
{
alert('Please specify Delivery Time as a positive integer');
frm.sb_delivery_time.focus();
frm.sb_delivery_time.select();
return(false);
}
if ( frm.sb_cash.checked==false && frm.sb_cheque.checked==false && frm.sb_credit.checked==false && frm.sb_bank.checked==false && frm.sb_loc.checked==false && frm.sb_escrow.checked==false && frm.sb_other_mode.value=='' )
{
alert('Please specify atleast one Payment Mode');
frm.sb_cash.focus();
return(false);
}
if( isNaN(frm.sb_shipping_cost.value) || frm.sb_shipping_cost.value < 0 || frm.sb_shipping_cost.value=='' )
{
alert('Please specify Shipping Cost as a positive number');
frm.sb_shipping_cost.focus();
frm.sb_shipping_cost.select();
return(false);
}
<?php ?>
return(true);
}
</script>
<form name="form123" method="post" action="<?php echo $_SERVER['PHP_SELF']; ?>" onSubmit="return validate_form(this);">
<table width="90%" border="0" align="center" cellpadding="0" cellspacing="0" class="onepxtable">
<tr>
<td class="titlestyle"> Post Sell Offer</td>
</tr>
<tr>
<td><table width="100%" border="0" align="center" cellpadding="2" cellspacing="5">
<tr>
<td colspan="3" class="innertablestyle"> <div align="center"><font class="normal">Sell
Offers: Posted - <strong><font class="red"><?php echo $sbsell_count; ?></font></strong>
Maximum Allowed - <strong><font class="red"><?php echo $sbrow_gro["sb_sell_cnt"]; ?></font></strong><br>
</font></div></td>
</tr>
<tr valign="top">
<td align="right" class="innertablestyle"><font class="normal"><strong>Categories<br>
</strong></font><font class="smalltext">(Max <strong><?php echo $sbrow_gro["sb_cat_cnt"]; ?></strong><?php echo ($sbrow_gro["sb_cat_cnt"]>1)?' categories':' category'; ?>)
</font></td>
<td><font class="red">*</font></td>
<td> <font class="smalltext">
<textarea name="category" cols="37" rows="5" readonly="readonly" id="category"><? echo $sb_cat_list;?></textarea>
<br>
<select name="cats" id="select2" >
<option value="0">Choose a category</option>
<?
$rs_query=mysql_query("select * from sbbleads_categories order by sb_pid");
while($rst=mysql_fetch_array($rs_query))
{
$cat_path="";
$child=mysql_fetch_array(mysql_query("select * from sbbleads_categories where sb_pid=".$rst["sb_id"]));
if($child)
{
continue;
}
$cat_path.=$rst["sb_cat_name"];
$par=mysql_query("select * from sbbleads_categories where sb_id=".$rst["sb_pid"]);
while($parent=mysql_fetch_array($par))
{
$cat_path=$parent["sb_cat_name"].">".$cat_path;
$par=mysql_query("select * from sbbleads_categories where sb_id=".$parent["sb_pid"]);
}
?>
<option value="<? echo $rst["sb_id"];?>" ><? echo $cat_path;?></option>
<?
}
?>
</select>
<input name="cid" type="hidden" id="cid" value="<? echo $cid_list;?>">
<input name="add" type="button" id="add" value="Add" onClick="add_category()">
<input name="Remove" type="button" id="Remove" value="Remove" onClick="remove_category()">
</font></td>
</tr>
<tr valign="top">
<td align="right" class="innertablestyle"><font class="normal"><strong>Title</strong></font></td>
<td><font class="red">*</font></td>
<td><font face="Arial, Helvetica, sans-serif" size="2">
<input name="sb_title" type="text" class=select id="sb_title" value="<?php echo $sb_title; ?>" size="30" maxlength="40">
</font></td>
</tr>
<tr valign="top">
<td align="right" class="innertablestyle"><font class="normal"><strong>Description</strong></font></td>
<td><font class="red">*</font></td>
<td valign="middle"> <font class='normal'>
<script language="JavaScript" type="text/javascript">
<!--
<?
$content = $sb_description;
$content = RTESafe($content);
?>//Usage: initRTE(imagesPath, includesPath, cssFile)
initRTE("images/", "", "");
//Usage: writeRichText(fieldname, html, width, height, buttons)
writeRichText('sb_description', '<?=$content?>', 450, 200, true, false);
//uncomment the following to see a demo of multiple RTEs on one page
//document.writeln('<br><br>');
//writeRichText('rte2', 'read-only text', 450, 100, true, false);
//-->
document.write("<br><font class='smalltext'>Description length must not exceed <?php echo $sbrow_con['sb_description_length'];?> characters</font>");
</script>
</font> <noscript>
<p><font class="normal"><b>Javascript must be enabled to use this
form.</b></font></p>
</noscript></td>
</tr>
<tr valign="top">
<td align="right" class="innertablestyle"><font class="normal"><strong>Quantity</strong></font></td>
<td><font class="red">*</font></td>
<td><font face="Arial, Helvetica, sans-serif" size="2">
<input name="sb_quantity" type="text" class=select id="sb_quantity" value="<?php echo $sb_quantity; ?>" size="30" maxlength="40">
</font><font face="Arial, Helvetica, sans-serif" size="2">
</font></td>
</tr>
<tr valign="top">
<td align="right" class="innertablestyle"><font class="normal"><strong>Keywords<br>
</strong></font><font class="smalltext">(Max <strong><?php echo $sbrow_gro["sb_keyword_cnt"]; ?></strong><?php echo ($sbrow_gro["sb_keyword_cnt"]>1)?' keywords':' keyword'; ?>)
</font></td>
<td><font class="red">*</font></td>
<td><input name="sb_keywords" type="text" class=select id="sb_keywords" value="<?php echo $sb_keywords; ?>" size="30" maxlength="40">
<br> <font class="smalltext">Please specify a comma seperated list
of keywords related to your product. Appropriate keywords will lead
more buyers to find your products.</font></td>
</tr>
<tr valign="top">
<td class="innertablestyle"> <div align="right"><strong><font class="normal">Location</font></strong></div></td>
<td width="6"><font class="red">*</font></td>
<td><font face="Arial, Helvetica, sans-serif" size="2">
<input name="sb_location" type="text" id="sb_location" value="<?php echo $sb_location; ?>">
</font></td>
</tr>
<tr valign="top">
<td class="innertablestyle"> <div align="right"><strong><font class="normal">Minimum
Order</font></strong></div></td>
<td><font class="red">*</font></td>
<td><font face="Arial, Helvetica, sans-serif" size="2">
<input name="sb_min_order" type="text" id="sb_min_order" value="<?php echo $sb_min_order; ?>" maxlength="20">
</font></td>
</tr>
<tr valign="top">
<td class="innertablestyle"> <div align="right"><strong><font class="normal">Price</font></strong></div></td>
<td><font class="red">*</font></td>
<td><font face="Arial, Helvetica, sans-serif" size="2">
<select name="sb_price_cur_id">
<option value="0">Select Currency</option>
<?
$rs_query=mysql_query("Select * from sbbleads_currencies where 1" );
while ($rs=mysql_fetch_array($rs_query))
{
?>
<option value="<?php echo $rs["sbcur_id"]; ?>"
<?php
if ( $rs["sbcur_id"]==$sb_price_cur_id)
{
echo " selected ";
}
?>
><?php echo $rs["sbcur_name"]; ?></option>
<?
}
?>
</select>
<input name="sb_price" type="text" id="sb_price" value="<?php echo $sb_price; ?>" size="5" maxlength="30">
</font></td>
</tr>
<tr valign="top">
<td width="40%" class="innertablestyle"> <div align="right"><strong><font class="normal">Samples
Available</font></strong></div></td>
<td><font class="red">*</font></td>
<td width="60%"><font face="Arial, Helvetica, sans-serif" size="2">
<select name="sb_samples_available" id="sb_samples_available">
<option value="yes" <?php echo ($sb_samples_available=="yes")?'selected':''; ?>>Yes</option>
<option value="no" <?php
if ( $sb_samples_available=="no" )
{
echo "selected";
}
?>>No</option>
</select>
</font></td>
</tr>
<tr valign="top">
<td width="40%" class="innertablestyle"> <div align="right"><strong><font class="normal">Product
Status</font></strong></div></td>
<td><font class="red">*</font></td>
<td width="60%"><font face="Arial, Helvetica, sans-serif" size="2">
<select name='sb_product_status' id="sb_product_status">
<option value="New" <?php
if ( $sb_product_status=="New" )
{
echo "selected";
}
?>>New</option>
<option value="Used" <?php
if ( $sb_product_status=="Used" )
{
echo "selected";
}
?>>Used</option>
</select>
</font></td>
</tr>
<tr valign="top">
<td width="40%" class="innertablestyle"> <div align="right"><strong><font class="normal">Delivery
Time</font></strong></div></td>
<td><font class="red">*</font></td>
<td width="60%"><input name="sb_delivery_time" type="text" value="<?php echo $sb_delivery_time; ?>" size="6">
<font class='normal'>Days </font></td>
</tr>
<tr valign="top">
<td width="40%" class="innertablestyle"> <div align="right"><strong><font class="normal">Payments
Mode</font></strong></div></td>
<td><font class="red">*</font></td>
<td width="60%"><font class="normal">
<input name="sb_cash" type="checkbox" id="sb_cash" value="yes" <?php
if ( strstr($sb_payment_mode,'cash') )
{
echo " checked ";
}
?>>
Cash <br>
<input name="sb_cheque" type="checkbox" id="sb_cheque" value="yes" <?php
if ( strstr($sb_payment_mode,'cheque') )
{
echo " checked ";
}
?>>
Cheque<br>
<font face="Arial, Helvetica, sans-serif"><font size="2">
<input name="sb_credit" type="checkbox" id="sb_credit" value="yes" <?php
if ( strstr($sb_payment_mode,'credit') )
{
echo " checked ";
}
?>>
</font></font> Credit card<br>
<font face="Arial, Helvetica, sans-serif"><font size="2">
<input name="sb_bank" type="checkbox" id="sb_bank" value="yes" <?php
if ( strstr($sb_payment_mode,'bank') )
{
echo " checked ";
}
?>>
</font></font> Bank transfer<br>
<font face="Arial, Helvetica, sans-serif"><font size="2">
<input name="sb_loc" type="checkbox" id="sb_loc" value="yes" <?php
if ( strstr($sb_payment_mode,'loc') )
{
echo " checked ";
}
?>>
</font></font> Letter of Credit<br>
<font face="Arial, Helvetica, sans-serif"><font size="2">
<input name="sb_escrow" type="checkbox" id="sb_escrow" value="yes" <?php
if ( strstr($sb_payment_mode,'escrow') )
{
echo " checked ";
}
?>>
</font></font> Escrow <br>
Other: <font face="Arial, Helvetica, sans-serif" size="2">
<input name="sb_other_mode" type="text" id="sb_other_mode" value="<?php echo $sb_other_mode; ?>">
</font> </font> </td>
</tr>
<tr valign="top">
<td class="innertablestyle"> <div align="right"><strong><font class="normal">Shipping
Cost</font></strong></div></td>
<td><font class="red">*</font></td>
<td><font face="Arial, Helvetica, sans-serif" size="2">
<input name="sb_shipping_cost" type="text" id="sb_shipping_cost" value="<?php echo $sb_shipping_cost; ?>" size="5">
</font></td>
</tr>
<tr valign="top">
<td align="right" class="innertablestyle"> </td>
<td> </td>
<td><input name="submit" type="submit" value="Post Now"></td>
</tr>
</table></td>
</tr>
</table>
</form>
<?
} //If showform = No? ends here
}
include_once("template1.php");
?>
================================
- Quantity ( kan være også - )
- Minimum Order ( kan være også - )
- Delivery Time ( kan være også - )
- Price ( kan være også - )
- Shipping Cost ( kan være også - )
Må ikke være obligatoriske.
Er der nogen der kan hjælpe?
TAK
